Data & privacy
IP infringement
| Risk | Related incident | Related paper |
|---|---|---|
| Copyrighted code | INC-001GPT-4 reproduced 100+ New York Times articles nearly verbatim when prompted with opening lines | |
| Copyrighted text | INC-002Perplexity’s answer engine republished Forbes’ paywalled investigation with near-verbatim text and minimal attribution | |
| Trademark slogans | INC-001GPT-4 reproduced 100+ New York Times articles nearly verbatim when prompted with opening lines | |
| Trademarked brand names | INC-002Perplexity’s answer engine republished Forbes’ paywalled investigation with near-verbatim text and minimal attribution | |
| Proprietary style mimicry | INC-003Spotify’s platform hosted an AI-generated King Gizzard impersonator for weeks before it was removed |
Personal data leakage
| Risk | Related incident | Related paper |
|---|---|---|
| Personal identifiers | INC-005McDonald’s AI hiring chatbot exposed up to 64M applicants’ data | |
| Sensitive personal records | INC-006Nx’s compromised npm package weaponized installed AI coding agents to exfiltrate developer credentials | |
| Credentials | INC-028A malicious npm package posing as an OpenAI Codex UI exfiltrated developer authentication tokens |
Business data leakage
| Risk | Related incident | Related paper |
|---|---|---|
| HR data | INC-007Microsoft 365 Copilot was exploited via ASCII smuggling to exfiltrate user data | |
| Operational data | INC-007Microsoft 365 Copilot was exploited via ASCII smuggling to exfiltrate user data | |
| Financial data | INC-008Anthropic’s Claude 3.7 Sonnet had its full 24,000-token system prompt extracted and published | |
| Proprietary data (inc. code) | INC-011GitHub’s Copilot Chat was hijacked via prompt injection to leak private repo code | |
| System prompt | INC-008Anthropic’s Claude 3.7 Sonnet had its full 24,000-token system prompt extracted and published |
Reliability
Hallucination (incorrect generation)
| Risk | Related incident | Related paper |
|---|---|---|
| Calls non-existent code | INC-012OpenAI’s ChatGPT and Google’s Gemini recommended a non-existent package that drew 30,000+ downloads once registered | |
| Instruction non-compliance | INC-012OpenAI’s ChatGPT and Google’s Gemini recommended a non-existent package that drew 30,000+ downloads once registered | |
| Inter-deliverable inconsistency | INC-012OpenAI’s ChatGPT and Google’s Gemini recommended a non-existent package that drew 30,000+ downloads once registered |
Hallucination (incorrect information)
| Risk | Related incident | Related paper |
|---|---|---|
| Outdated facts | INC-013Air Canada’s chatbot invented a refund policy, and the airline was held liable | |
| Premature assertions | INC-014Apple’s Intelligence notification summaries misrepresented BBC headlines, forcing Apple to pause the feature | |
| Ground truth contradictions | INC-013Air Canada’s chatbot invented a refund policy, and the airline was held liable | |
| Misleading facts | INC-014Apple’s Intelligence notification summaries misrepresented BBC headlines, forcing Apple to pause the feature | |
| Misleading confidence | INC-015Sullivan & Cromwell apologized to a bankruptcy judge for AI hallucinations in a Chapter 15 filing | |
| Misleading citations | INC-015Sullivan & Cromwell apologized to a bankruptcy judge for AI hallucinations in a Chapter 15 filing | |
| Self-contradiction | INC-016Google’s AI Overviews falsely told searchers a Minnesota solar firm was being sued |
Incorrect tool call
| Risk | Related incident | Related paper |
|---|---|---|
| Incorrectly executed action | INC-019McDonald’s IBM-built AI drive-thru misinterpreted spoken orders, ending the trial | |
| Unprompted action | INC-020Sakana AI’s research agent rewrote its own code to remove a runtime limit it kept hitting | |
| Incomplete action | INC-019McDonald’s IBM-built AI drive-thru misinterpreted spoken orders, ending the trial |
Security
Unauthorized actions
| Risk | Related incident | Related paper |
|---|---|---|
| Unauthorized transaction | INC-022Chevrolet of Watsonville’s ChatGPT-powered chatbot was manipulated into ‘selling’ a 76,000Tahoefor1 | |
| Unauthorized communication | INC-036DPD’s customer-service chatbot swore at a customer and disparaged the company | |
| Unauthorized system actions | INC-029A hidden prompt injection in a Word document turned Microsoft Copilot for Word into a self-propagating AI worm | |
| Unauthorized cross-system data transfer | INC-022Chevrolet of Watsonville’s ChatGPT-powered chatbot was manipulated into ‘selling’ a 76,000Tahoefor1 |
Insecure outputs
| Risk | Related incident | Related paper |
|---|---|---|
| Hyperlinks (URLs) | INC-030OpenAI’s ChatGPT recommended cloned scam websites to shoppers | |
| Code patterns or blocks | INC-029A hidden prompt injection in a Word document turned Microsoft Copilot for Word into a self-propagating AI worm |
Insecure action
| Risk | Related incident | Related paper |
|---|---|---|
| Install insecure code | INC-031Amazon’s Q Developer VS Code extension shipped a hacker-injected data-wiping prompt | |
| Fatal code execution | INC-031Amazon’s Q Developer VS Code extension shipped a hacker-injected data-wiping prompt |
Safety
Physical harm
| Risk | Related incident | Related paper |
|---|---|---|
| Dangerous instructions | INC-032Discord’s Clyde chatbot was tricked into outputting weapon instructions via a roleplay jailbreak | |
| Medically unsafe guidance | INC-034OpenAI’s ChatGPT reportedly suggested bromide as a salt substitute, and a man was hospitalized for 3 weeks | |
| Self-harm content | INC-045Meta’s AI chatbot engaged teen test accounts on suicide, self-harm and eating disorders instead of offering help | |
| Suicide content | INC-035OpenAI’s ChatGPT allegedly validated a 16-year-old’s suicidal thoughts over months, and his parents sued |
Emotional harm
| Risk | Related incident | Related paper |
|---|---|---|
| Hostile / aggressive behavior | INC-037Google’s Gemini told a college student seeking homework help to ‘please die’ | |
| Triggering content | INC-037Google’s Gemini told a college student seeking homework help to ‘please die’ |
Inappropriate content
| Risk | Related incident | Related paper |
|---|---|---|
| Harassment | INC-037Google’s Gemini told a college student seeking homework help to ‘please die’ | |
| Hate speech | INC-042OpenAI’s Sora 2 app generated violent, racist and antisemitic videos within weeks of its launch | |
| Sexual content excluding minors | INC-046FoloToy’s Kumma AI teddy bear told researchers where to find knives and discussed sexual fetishes | |
| Violent content | INC-042OpenAI’s Sora 2 app generated violent, racist and antisemitic videos within weeks of its launch | |
| Illegal conduct advice | INC-040OpenAI’s ChatGPT generated fake South Korean military ID images for a North Korean Kimsuky phishing campaign | |
| Out of scope outputs | INC-038Bing’s chatbot was steered over a two-hour conversation into rule-breaking, destructive content | |
| Code and structured data outputs | INC-040OpenAI’s ChatGPT generated fake South Korean military ID images for a North Korean Kimsuky phishing campaign | |
| Biased output | INC-041Six major chatbots drafted phishing emails aimed at seniors in a Reuters test, and 11% of recipients clicked |
High-risk domain engagement
| Risk | Related incident | Related paper |
|---|---|---|
| Medical advice | INC-034OpenAI’s ChatGPT reportedly suggested bromide as a salt substitute, and a man was hospitalized for 3 weeks | |
| Legal advice | INC-044New York City’s MyCity business chatbot advised users to break the law | |
| Financial advice | INC-044New York City’s MyCity business chatbot advised users to break the law | |
| Crisis advice | INC-047Character.AI’s companion chatbot allegedly posed as a therapist and romantic partner to a teen who died by suicide | |
| Therapy/psychological advice | INC-050Meta’s Instagram AI Studio chatbots claimed to be licensed therapists, inventing licence numbers and credentials |
Company defined risk
| Risk | Related incident | Related paper |
|---|---|---|
| Prohibited topics | INC-046FoloToy’s Kumma AI teddy bear told researchers where to find knives and discussed sexual fetishes | |
| Vulnerable users | INC-045Meta’s AI chatbot engaged teen test accounts on suicide, self-harm and eating disorders instead of offering help |
Accountability
Transparency
| Risk | Related incident | Related paper |
|---|---|---|
| Bypass AI disclosure | INC-048Bland AI’s voice agent told callers it was human, including when not instructed to |
37.782274° N -122.392147° WFIG. A (SITE INDEX)
Artificial Intelligence Underwriting Company
CodeStructural unita.AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.b.Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.c.Crosswalks to AI regulations, standards, and security frameworks.d.Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.
I. Standard
II. Learn
III. Office
100© AIUC — ALL RIGHTS RESERVED